Netoloji Software E-Flow Unrestricted File Upload Vulnerability Allowing Stored Cross-Site Scripting

Vulnerability

A vulnerability in Netoloji Software E-Flow prior to version 3.23.00 allows for unrestricted file uploads of dangerous file types. This issue also involves improper input neutralization during web page generation, leading to cross-site scripting (XSS) vulnerabilities. Additionally, the vulnerability allows access to functionalities not properly constrained by access control lists (ACLs) and enables file content injection.

Impact

Exploitation of this vulnerability could lead to stored cross-site scripting, where injected scripts are executed in the context of the user.

Remediation

Users are advised to update to version 3.23.00 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.8
exploitability
5.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.